Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Network Security-equipment Security reinforcement

Shulou Source: shulou.com Published: 2022-06-01 06:12:33 10月04日 Update

Network equipment is also a very important equipment at the network boundary. It is the trunk road of the entire data center. There must be no mistakes. In the past two days, Nexus network equipment has been simply strengthened. The main operations are summarized as follows:

1. Create a read-only account in Nexus, such as to view configuration and view other information. Because Nexus has a good and easy-to-operate RBAC control mechanism, this is a good implementation.

A. First create a role called maintain and determine the executable command

N7K(config)#rolename maintain

N7K(config)#rule1 permit command show running-config

N7K(config)#rule2 permit command show mac address-table

N7K(config)#rule3 permit command show access-lists

B. Create an account belonging to maintain, maintainonly

N7K(config)#usernamemaintainonly secret 0 xxxxxx role maintain

C. Use maintainonly login to confirm

N7K# ? ... tried with question marks here, and there was no show command.

end Go to exec mode

exit Exit from command interpreter

N7K #show run...... here is the direct execution is this OK

! Command: show running-config

! Time: Thu Sep 4 13:35:522014

version 6.1(2)

switchname N7K

.

.

.N7K# show int...... not allowed to view interface, reality permissiondenied.

% Permission deniedfor the role

2. Add bannermotd warning prompt to the switch, unauthorized people are not allowed to log in to the device.

3. Change the device to ssh login

Feather ssh

No feather telnet

4. Add access-class access control to vty and set login idle timeout to 10min.

Creating an ACL:

Ip access-listlogin_auth

1 permit ip 172.10.10.0/24 any

Then call below vty

Line vty

Access-class login_auth in

Exec-timeout 10

5. Enable root protection on some necessary interfaces

spanning-tree guard root

Enable some other security features

no ip redirects

no ip unreachables

no ip proxy-arp

That's all for now, and we'll continue next time.

Tags: Equipment login network account security command network equipment control protection reinforcement importance necessity trunk trunk switch information security interface data data center Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno vpn OPPO Reno Docker Microsoft Shulou Technology